BTC $57879.6829
ETH $2902.4199
BNB $550.6354
SOL $122.5910
stETH $2897.6439
XRP $0.4936
DOGE $0.1252
TON $4.7319
ADA $0.4337
AVAX $31.8227
TRX $0.1189
wstETH $3375.0481
WETH $2893.7856
WBTC $57722.7233
DOT $6.4925
BCH $408.3240
LINK $12.9268
MATIC $0.6574
UNI $6.7684
ICP $12.6554
LTC $77.1376
DAI $1.0011
FDUSD $0.9979
CAKE $2.4598
RNDR $7.2344
IMX $1.9072
NEAR $6.0653
ETC $24.6728
HBAR $0.0958
MNT $0.9138
STX $2.0321
FIL $5.3555
OKB $48.2104
ATOM $8.4918
PEPE $0.0000
VET $0.0345
KAS $0.1059
MKR $2612.4755
TAO $360.1816
WIF $2.3864
USDE $0.9986
GRT $0.2291
XMR $117.7030
XLM $0.1061
FET $1.9379
INJ $22.6848
CRO $0.1279
BTC $57879.6829
ETH $2902.4199
BNB $550.6354
SOL $122.5910
stETH $2897.6439
XRP $0.4936
DOGE $0.1252
TON $4.7319
ADA $0.4337
AVAX $31.8227
TRX $0.1189
wstETH $3375.0481
WETH $2893.7856
WBTC $57722.7233
DOT $6.4925
BCH $408.3240
LINK $12.9268
MATIC $0.6574
UNI $6.7684
ICP $12.6554
LTC $77.1376
DAI $1.0011
FDUSD $0.9979
CAKE $2.4598
RNDR $7.2344
IMX $1.9072
NEAR $6.0653
ETC $24.6728
HBAR $0.0958
MNT $0.9138
STX $2.0321
FIL $5.3555
OKB $48.2104
ATOM $8.4918
PEPE $0.0000
VET $0.0345
KAS $0.1059
MKR $2612.4755
TAO $360.1816
WIF $2.3864
USDE $0.9986
GRT $0.2291
XMR $117.7030
XLM $0.1061
FET $1.9379
INJ $22.6848
CRO $0.1279
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Bug in Hyundai and Genesis cars allows complete takeover


    The discovered vulnerability affects the mobile applications of Hyundai and its luxury brand Genesis, which owners use to track the status of their cars, schedule maintenance, unlock doors and start the engine. According to Sam Curry, the hacker and bug hunter who discovered the vulnerability, the mobile apps for Hyundai and Genesis vehicles only provide functionality to authorized users. However, Sam and his team found that the server did not require users to verify their email address. In addition, it turned out that authorization can be bypassed by adding CRLF characters to the end of the victim's address during the creation of a new account. Thus, it is possible to create a new account in the application with an already existing email address.

    The new account was given a JSON web token (JWT) that matches the real email address, allowing the hacker to access the victim's app account and then the car.

    To test the exploit, the researchers ran an experiment on one of their vehicles. And it worked - Sam's team was able to unlock the car using a new account linked to the victim's modified email address.

    The researchers even wrote a Python script that allows them to take control of a car, requiring only the victim's email address from a potential car thief.

    But there is also good news. The researchers reported the vulnerability to Hyundai, and according to Curry, it has been patched.

    Author DeepWeb
    Liquid ecstasy
    LastPass has again become a victim of hackers

    Comments 0

    Add comment